CVE-2022-31670

CVSS 3.1 Score 7.7 of 10 (high)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 285

Summary

CVE-2022-31670 vulnerability affects Harbor, an open-source container registry. The issue lies in Harbor's failure to validate user permissions when updating tag retention policies. An attacker can exploit this flaw by attempting to update a tag retention policy with an id belonging to a project the user doesn't have access to. By doing so, the attacker could modify tag retention policies in other projects, compromising their data retention settings. This vulnerability poses a significant risk, especially in multi-tenant environments, and requires immediate patching.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share